CVE-2023-38000


Auth. Stored Cross-Site Scripting (XSS) vulnerability in WordPress core and Gutenberg plugin via Navigation Links Block

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.



We have discovered 494,516 live websites that are affected by CVE-2023-38000.

Contact us to get more info




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Versions
  • from 5.9 through 5.9.7
  • from 6 through 6.0.5
  • from 6.1 through 6.1.3
  • from 6.2 through 6.2.2
  • from 6.3 through 6.3.1
Total Vulnerable Versions780
Vulnerable Domains494,516 live websites (4.34% of WordPress install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-38000 and the relative popularity of websites


Details

  • Published - Oct 13, 2023
  • Updated - Oct 13, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)
  • Edouard Lamoine (Patchstack) (finder)





Countries

United States122,286 websites



Germany52,655 websites
GB27,608 websites
France22,433 websites
Netherlands21,040 websites
Italy19,999 websites
Poland18,669 websites
Japan15,621 websites
Spain15,284 websites
Russia12,812 websites

TLDs

.com192,777 websites
.de35,495 websites
.org22,380 websites
.nl17,466 websites
.co.uk15,788 websites
.net13,982 websites
.pl13,685 websites
.it13,536 websites
.ru10,535 websites
.com.br9,561 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-38000 through included software libraries and plugins.



References


Websites affected by CVE-2023-38000

Top websites that are affected by CVE-2023-38000. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***************.org United States***
***.******.com United States***
***.*********.com United States***
**********.ca Canada*,***
****.*******.org United States*,***
**********.org United States*,***
***.*********.com United States*,***
********.com Singapore*,***
***.************.com United States*,***
***.******.de Germany*,***
See full domain list